2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57774 | MEDIUM | 4.8 | 0.3% | Jan 16, 2025 | A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01.... |
| CVE-2024-57773 | MEDIUM | 4.8 | 0.3% | Jan 16, 2025 | A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 ... |
| CVE-2024-57772 | MEDIUM | 4.8 | 0.3% | Jan 16, 2025 | A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 ... |
| CVE-2024-57771 | MEDIUM | 4.8 | 0.3% | Jan 16, 2025 | A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allow... |
| CVE-2024-57770 | HIGH | 8.8 | 0.6% | Jan 16, 2025 | JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContr... |
| CVE-2024-57769 | HIGH | 8.8 | 0.6% | Jan 16, 2025 | JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listDa... |
| CVE-2024-57768 | CRITICAL | 9.8 | 0.5% | Jan 16, 2025 | JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRo... |
| CVE-2024-50633 | HIGH | 7.5 | 0.6% | Jan 16, 2025 | A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by... |
| CVE-2024-41746 | MEDIUM | 6.1 | 0.2% | Jan 16, 2025 | IBM CICS TX Advanced 10.1, 11.1, and Standard 11.1 is vulnerable to stored cross-site scripting. This vulnerability allo... |
| CVE-2024-37181 | LOW | 2.6 | 0.1% | Jan 16, 2025 | Time-of-check time-of-use race condition in some Intel(R) Neural Compressor software before version v3.0 may allow an au... |
| CVE-2024-57611 | LOW | 3.5 | 0.1% | Jan 16, 2025 | 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/doAdminAction.php?act=editShop&s... |
| CVE-2024-57162 | HIGH | 7.2 | 0.5% | Jan 16, 2025 | Campcodes Cybercafe Management System v1.0 is vulnerable to SQL Injection in /ccms/view-user-detail.php. |
| CVE-2024-57161 | MEDIUM | 4.3 | 0.2% | Jan 16, 2025 | 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit... |
| CVE-2024-57160 | MEDIUM | 4.3 | 0.2% | Jan 16, 2025 | 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaTask/edit.html. |
| CVE-2024-57159 | LOW | 3.5 | 0.1% | Jan 16, 2025 | 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/add.... |
| CVE-2024-50563 | CRITICAL | 9.8 | 0.6% | Jan 16, 2025 | A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, F... |
| CVE-2024-13387 | MEDIUM | 6.4 | 0.3% | Jan 16, 2025 | The WP Responsive Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprtabs' shor... |
| CVE-2024-13355 | MEDIUM | 5.4 | 0.4% | Jan 16, 2025 | The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited fi... |
| CVE-2024-12615 | MEDIUM | 6.5 | 0.5% | Jan 16, 2025 | The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX ac... |
| CVE-2024-12614 | MEDIUM | 4.3 | 0.4% | Jan 16, 2025 | The Passwords Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit... |
| CVE-2024-12613 | HIGH | 7.5 | 0.5% | Jan 16, 2025 | The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX fu... |
| CVE-2024-12427 | MEDIUM | 5.3 | 0.4% | Jan 16, 2025 | The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability c... |
| CVE-2024-48885 | CRITICAL | 9.1 | 0.8% | Jan 16, 2025 | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder... |
| CVE-2024-45331 | HIGH | 7.8 | 0.2% | Jan 16, 2025 | A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 throug... |
| CVE-2024-12226 | MEDIUM | 6.5 | 0.3% | Jan 16, 2025 | In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes s... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now